exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 282 discussion

Actual exam question from CompTIA's CAS-004
Question #: 282
Topic #: 1
[All CAS-004 Questions]

A SaaS startup is maturing its DevSecOps program and wants to identify weaknesses earlier in the development process in order to reduce the average time to identify serverless application vulnerabilities and the costs associated with remediation. The startup began its early security testing efforts with DAST to cover public-facing application components and recently implemented a bug bounty program. Which of the following will BEST accomplish the company’s objectives? (Choose two.)

  • A. IAST
  • B. RASP
  • C. SAST
  • D. SCA
  • E. WAF
  • F. CMS
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
deeden
1 month ago
Selected Answer: CD
While IAST identifies vulnerabilities during runtime, it is typically used in testing or staging environments rather than early in the SDLC. It complements but does not replace SAST or SCA.
upvoted 1 times
...
Bright07
1 month, 1 week ago
Selected Answer: AC
A. IAST (Interactive Application Security Testing): IAST integrates into the development environment and actively tests applications while they are running. It allows for real-time feedback and can detect vulnerabilities earlier in the development process. By analyzing the code and behavior of an application while it is running, IAST helps identify vulnerabilities during the testing phase before the app is deployed. This is ideal for identifying issues earlier in the development cycle. C. SAST (Static Application Security Testing): SAST analyzes the source code, bytecode, or binary files of an application for vulnerabilities before the application runs. Since it works on the codebase itself, it allows developers to detect vulnerabilities early in the development process, thus preventing vulnerabilities from being deployed. This is especially useful in serverless environments, where vulnerabilities could be introduced by misconfigurations or insecure code in the serverless functions.
upvoted 1 times
...
EAlonso
6 months ago
AD, they already have implemented DAST, so based in the bounty program they need to check the code (included in A...IAST=DAST+SAST) and also need SCA, this way have covered almost any bug reported.
upvoted 1 times
EAlonso
6 months ago
CD, for the same reason I'm moving from A to C
upvoted 1 times
...
...
isaphiltrick
6 months, 1 week ago
Selected Answer: CD
SAST: Analyzes source code for vulnerabilities before deployment. SCA: Identifies and manages risks associated with third-party components.
upvoted 2 times
...
HappyG
10 months, 1 week ago
Selected Answer: AD
IAST (Interactive Application Security Testing): IAST solutions can analyze applications during runtime and provide real-time feedback on potential vulnerabilities. By integrating IAST into the DevSecOps pipeline, the startup can identify security weaknesses earlier in the development process, allowing developers to address issues as they arise. IAST complements DAST by providing deeper insights into application behavior and vulnerabilities while reducing false positives. SCA (Software Composition Analysis): SCA tools help identify and manage open-source components and dependencies within applications. Since many serverless applications heavily rely on third-party libraries and frameworks, SCA can help detect vulnerabilities in these components early in the development lifecycle. By integrating SCA into the DevSecOps pipeline, the startup can proactively identify and remediate vulnerabilities related to third-party dependencies, reducing the risk of exploitation and associated remediation costs.
upvoted 2 times
...
e020fdc
11 months ago
Selected Answer: CD
I’d say C and D based on the following definitions. A – IAST: IAST identifies security vulnerabilities in running applications while providing developers with the relevant lines of code and contextual remediation advice. B – RASP : Runtime Application Self-Protection (RASP) is a tool that can detect attacks on applications as they occur. A RASP implementation can protect applications from malicious data and behavior by analyzing how the program behaves. If the application's behavior indicates something is wrong, RASP can help stop the threat. C – SAST: Static application security testing is used to secure software by reviewing the source code of the software to identify sources of vulnerabilities.
upvoted 1 times
e020fdc
11 months ago
D – SCA: Software composition analysis (SCA) is an automated process that identifies the open source software in a codebase. This analysis is performed to evaluate security, license compliance, and code quality. E – WAF: A WAF or web application firewall helps protect web applications by filtering and monitoring HTTP traffic between a web application and the Internet. F – CMS: A Content Management System (CMS) is a software platform that allows users to build and manage a website with limited technical knowledge and resources.
upvoted 2 times
...
...
userguy890
11 months ago
Selected Answer: CD
IAST is the same as DAST + SAST so best to use SAST with SCA
upvoted 2 times
...
32d799a
1 year, 3 months ago
Selected Answer: AC
A. IAST (Interactive Application Security Testing) - IAST tools typically combine elements of both SAST and DAST and are designed to identify security vulnerabilities in applications as they are running, especially in real-time environments; C. SAST (Static Application Security Testing) - SAST analyzes the source code, bytecode, or binary code of applications for vulnerabilities without executing the code. By doing this analysis at the code level, SAST can identify vulnerabilities early in the SDLC.
upvoted 2 times
...
Ariel235788
1 year, 3 months ago
Selected Answer: AC
To identify weaknesses earlier in the development process for serverless application vulnerabilities and reduce costs associated with remediation, the startup should consider the following options: A. IAST (Interactive Application Security Testing): IAST solutions can provide real-time feedback during the development process by analyzing code and identifying vulnerabilities. Unlike DAST (Dynamic Application Security Testing), which tests the application from the outside, IAST works from within the application, making it well-suited for identifying vulnerabilities in serverless applications. C. SAST (Static Application Security Testing): SAST tools can analyze the source code and identify potential vulnerabilities before the application is even deployed. It can be integrated into the development pipeline, allowing developers to catch and remediate vulnerabilities early in the process. Both IAST and SAST can help identify weaknesses early in the development process, reducing the time to identify vulnerabilities and the associated remediation costs.
upvoted 3 times
...
Meep123
1 year, 3 months ago
Selected Answer: AC
Since this is for early in development, I'm going with IAST and SAST.
upvoted 2 times
Meep123
1 year, 3 months ago
well... IAST=DAST+SAST, I'm actually going to go with SAST and SCA... oops lol
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago